Recently named by Newsweek as one of the Best American Mid-Sized Workplaces in 2026, Rohde & Schwarz is expanding our Cybersecurity team. The Cybersecurity Engineer, Governance & Compliance position plays a critical role in supporting the development, delivery, and sustainment of secure mission-critical systems across Rohde & Schwarz North America. This position will serve as a versatile member of the U.S. cybersecurity organization while providing primary expertise in cybersecurity governance, compliance, risk management, security requirements, and security documentation.
The engineer will work across the cybersecurity lifecycle, collaborating with engineering, product development, program management, customers, and global cybersecurity teams. While Governance & Compliance will be the position's primary area of specialization, the successful candidate will also support broader cybersecurity engineering activities including security assessments, system architecture, vulnerability management, testing, product security, and customer/program support.
Initially, the position will support Air Traffic Control (ATC) programs, with the opportunity to support additional Rohde & Schwarz products, programs, and business areas as the North American cybersecurity capability grows. This position requires being onsite in our Frederick, MD facility and requires US citizenship.
Your tasks
- Develop, maintain, and improve cybersecurity governance processes, standards, procedures, templates, and technical guidance.
- Analyze customer, contractual, regulatory, and internal cybersecurity requirements and translate them into actionable system and engineering requirements.
- Map technical and operational security controls to applicable frameworks, primarily NIST SP 800-53, as well as NIST CSF, DISA STIGs, CIS Benchmarks, ISO 27001, and other applicable customer or industry requirements.
- Develop and maintain System Security Plans (SSPs), security assessment reports, control implementation summaries, risk assessments, risk matrices, security procedures, and related cybersecurity documentation.
- Maintain traceability between customer requirements, system requirements, implemented security controls, verification activities, and supporting evidence.
- Support cybersecurity risk management activities including risk identification, analysis, treatment, acceptance, and residual risk documentation.
- Participate in customer cybersecurity meetings, design reviews, audits, assessments, and approval activities.
- Assist engineering teams in interpreting cybersecurity requirements and determining practical implementation approaches.
- Perform cybersecurity assessments of systems, subsystems, COTS products, software, and embedded components.
- Support threat modeling, attack-surface analysis, security architecture reviews, and security design activities.
- Review network architectures, interfaces, data flows, trust boundaries, segmentation, authentication mechanisms, logging, and security controls.
- Support Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), customer deployments, onsite assessments, and other cybersecurity project activities when required.
- Contribute to cybersecurity process improvement, standardization, training, knowledge transfer, automation, and development of reusable security artifacts.
- Maintain awareness of evolving U.S. cybersecurity regulations, standards, customer requirements, and industry best practices.
- Support the broader cybersecurity organization as priorities, programs, and customer requirements evolve.